Khoros Cookies Datasheet (Community, Care, Marketing, Khoros Bot).
Cookies are small data files stored in web browsers to track usage and enable useful services and features when using Khoros Services or interacting with Khoros. This document provides information on the standard cookies used by Khoros Services and Khoros generally and how to reject or delete those cookies should users choose to do so. Understand that restricting cookies can have an adverse impact on the functionality and the online user experience when interacting with Khoros and Khoros Services. We classify the cookies typically used by Khoros and Khoros Services into the four broad categories described below. Type Classification Description Example 1 Strictly necessary These cookies are necessary for the proper functioning of the community, such as tracking a user session, or accessing secure areas. Session cookie used to pin a logged-in session to a browser 2 Performance The information these cookies collect is anonymous and is used to collect aggregate data including information about the pages users visit. Cookies delivered by Omniture WebAnalytics and Google Analytics for purposes of aggregate reporting 3 Functional These cookies allow websites to remember preferences and settings, such as your username, language, region, font size, and so on. Cookie used to hold a user’s username as part of a “remember me” feature 4 Tracking, targeting and sharing These cookies remember that you've visited a website, a particular web page, and/or track your activities on the site. This information is sometimes shared with third party advertisers for serving targeted online advertising or other personalized content. Cookies used to track visitor activity on an individual basis can be used by Khoros or its third party business partners to serve personalized content, and/or later aggregated and used to analyze website traffic and trends. How to control cookies Some cookies are necessary for the proper operation of Khoros Services and disabling or removing them may have an adverse impact on the proper functioning and user experience. However, users may choose to view, block, or remove cookies set by Khoros Services through their web browser settings (or any website cookies for that matter). Consult the help feature for your specific browser to find how. Here are some useful links for your convenience. Microsoft Internet Explorer Privacy Settings and Information Google Chrome Privacy Settings and Information Mozilla Firefox Privacy Settings and Information Apple Safari Privacy Settings and Information Also, you may choose to consult an external and independent third party website such as AboutCookies.org or www.youronlinechoices.eu/ if you are in the European Union which provides comprehensive information on a variety of browsers and how to control or change their respective privacy settings. Cookies used by Khoros The following standard cookies are used by: Khoros Community Community Analytics Khoros Care Khoros Marketing Khoros Bot Atlas Turning off or removing these cookies may have an adverse impact on the proper functioning and user experience when interacting with Khoros and/or using Khoros Services. Khoros Community Cookies Cookie Name Type Description and Purpose Expiration Time/Type If removed, disabled, or not accepted AWSALB 1 AWS sticky session cookie required for load balancer routing. See this document for further information. Request (persists for 7 days) Sticky session won't work and some functionality will break. AWSALBCORS 1 For continued stickiness support with CORS use cases after the Chromium update, we are creating additional stickiness cookies for each of these duration-based stickiness features named AWSALBCORS (ALB). See https://docs.aws.amazon.com/ elasticloadbalancing/latest/ application/sticky-sessions. html for further information. Request (persists for 7 days) _ga 2 Distinguishes users using a unique ID. It is used by Google Analytics to calculate visitor, session, and campaign data. By default, the configuration setting that sets this cookie is disabled. File a Support ticket to request enablement. 2 years (persistent) Visitor and session data will not be tracked and will not be available to Google Analytics !lithiumSSO:{client_id} 1 Used for passing authentication information to Khoros This cookie is a cancel cookie. Khoros sets this cookie so that we don't re-read the original lithiumSSO cookie set with SSO. session SSO will not be functional for the user LiSESSIONID 1 Session management session User cannot log in, and is treated as an anonymous user lia.anon.{setting or config name} 3 Stores community-wide configurations and settings for anonymous users 1 year (persistent) Community behavior will follow defaults and any UI convenience changes made by the user will be ignored. liSdkOptions:{communityId} 3 Dropped when a Studio user navigates to Studio > Advanced > SDK and clicks Submit after checking the View as anonymous checkbox. The cookie allows developers to sign out of the community but still have it find the URL to use for rendering a skin that is hosted via the Community Plugin SDK. This cookie is used only on stage sites. 1 month or when the View as anonymous checkbox is unselected The community will serve the URL for the skin set on the stage site instead of the URL to the locally hosted skin (so local SASS development will not work when the user is signed out) lithium.anonymous. usersetting.{setting name} 3 Remembers user preferences 1 year (persistent) The community will not remember the user’s setting preferences lithium.anonymous. usersetting.profile. language 3 Remembers language preferences 1 year (persistent) The community will not remember the user’s language preferences. The language will default to the native language defined for the community. lithiumLogin:{community id} 3 Keeps users logged in when they make a request after their session has expired. It is triggered when a user checks Save login name and password. The cookie is encrypted and includes a unique user secure ID in the database. 30 days (persistent) The "auto login" and "remember me" features will not work LithiumNotifications 3 Temporarily stores Realtime Notification messages (Toast messages) session Realtime notification toasts may not appear (pop-up) after a page transition. LithiumUserInfo 1 Session management session The user will not be able to view secure pages and will be redirected to the login page LithiumUserSecure 1 Secure Session management session The user will not be able to view secure pages and will be redirected to the login page. LithiumVisitor 1 Replaces VISITOR_BEACON. Khoros currently uses both for backward compatibility. This cookie computes billing visits, registered billing visits, visits, registered visits, and unique visitors metrics. The cookie is encrypted and stores when it was first issued, when it was last seen by Khoros, an unique visitor ID (which is unique per visitor’s browser). Configurable (Default = 6 Months) Note: To change the default value, contact Khoros Support. Visits and unique visitors metrics will not be accurate. There will be a new billable visit on each new request. Customers on billing visits model will be affected. P{poll_id}U{user_id}R{reset_count} 3 Tracks when a user has voted in a poll and tracks the answer value. The cookie is used to prevent a user from voting multiple times in a single poll. The cookie is only placed if Use cookies to prevent multiple votes is enabled in Community Admin. 14 days If the user is an anonymous user, the user will be able to vote multiple times when the cookie is cleared. If the user is logged in, votes, and then clears the cookie, they are not allowed to revote. PushyAuthToken 1 Authenticates the user for a session with Realtime Notifications service (Pushy) Manually cleared when the user logs out or when their session expires due to inactivity WebSocket connections to the Realtime Notification service will fail with a 403 Forbidden error and the user will not see realtime notifications. VISITOR_BEACON 1 Computes billing visits, registered billing visits, visits, registered visits, and unique visitors metrics. The cookie is encrypted and stores, when it was first issued, when it was last seen by Khoros, the user ID, and its own unique ID. Configurable (Default = 6 Months) Note: To change the default value, contact Khoros Support. Visits and unique visitors metrics will not be accurate. There will be a new billable visit on each new request. Customers on billing visits model will be affected. VISITORID 1 Distinguishes between human and bot traffic 3 years (session) Defeats the bot detection mechanism. (May see increased spam on the community.) ValueSurveyParticipation 3 Stores a timestamp storing the creation time of this cookie, which is used in value survey trigger logic. Default is 90 days. Configurable in Community Admin The user will get multiple prompts to take a survey ValueSurveyVisitorCount 3 Stores the survey visit count of the user, which is used in logic that determines when a survey is triggered. This cookie is used in conjunction with the ValueSurveyParticipation cookie. When the ValueSurveyParticiation is set, the count for ValueSurveyVisitorCount cookie is reset to 0. Expires when the ValueSurveyParticipation cookie is either set or expires The user will not be prompted to take a survey until the count defined in the Delay before prompting user with survey field in Community Admin > Features > Value Surveys > Settings is met. ValueSurveyCompletion (Aurora) 3 Stores whether the user has completed or declined the survey. This cookie is used to determine that the survey is not served to the user again until the cookie expires. Configurable (default = 30 days if declined or abandoned and 90 days if completed) This cookie is not dropped if the user has rejected or turned off third-party cookies. If this cookie is cleared, the user may be prompted with an additional survey depending on their configured settings. ValueSurveyVisits (Aurora) 3 Stores the survey visit count of the user, which is used in logic that determines when a survey is triggered. This cookie is used in conjunction with the ValueSurveyParticipation cookie. When the ValueSurveyParticipation is set, the count for ValueSurveyVisits cookie is reset to 0. Expires when the ValueSurveyParticipation cookie is either set or expires The user will not be prompted to take a survey until the count defined in the Present survey after this many visits field in Community Admin > Content Features > Community Experience Survey > Survey Behaviors is met. LithiumCookiesAccepted (for Cookie Banner v1) 1 Stores the information of whether the user has given explicit consent by clicking "Accept" on the cookie banner to store Type 2, Type 3 & Type 4 cookies. For Cookie Banner v1, this cookie stores: -'1' if the user has explicitly clicked "Accept" in the cookie banner. -'2' if user clicked "Reject". Configurable (Default = 6 months). This cookie is not session specific (persistent) and will be maintained across sessions. This cookie is not dropped if OOTB cookie banner is disabled. If the banner is enabled and this cookie is explicitly removed from the browser, the cookie banner will appear again and Type 2, Type 3 & Type 4 cookies will not be stored unless the user clicks “Accept” again. LithiumNecessaryCookiesAccepted (for Cookie Banner v2 and Aurora) 1 Stores the information of whether the user has given explicit consent by clicking "Accept", "Reject" or "Confirmed" their choices from options under "Preferences" on the cookie banner to store Type 1 cookies. For Cookie Banner v2 this cookie stores: -'0' when the OOTB cookie banner for the site is enabled and user has not explicitly clicked "Accept" or "Reject" or "Confirmed" their choices from "Preferences". - For Classic: '0' when the OOTB cookie banner for the site is enabled and user clicked "Reject". - For Aurora: "1" when the OOTB cookie banner for the site is enabled and user clicked "Reject". -'1' if the user has explicitly clicked "Accept" or "Confirmed" their choices from "Preferences". Irrespective of the value, Type 1 cookies are always stored in the browser. Configurable (Default = 6 months). This cookie is not session specific (persistent) and will be maintained across sessions. This cookie is not dropped if OOTB cookie banner is disabled. If the banner is enabled, removing or deleting this cookie from the browser will not impact any Type 1 cookies that are stored in the browser. LithiumFunctionalCookiesAccepted (for Cookie Banner v2) 1 Stores the information of whether the user has given explicit consent by clicking "Accept", "Reject" or "Confirmed" their choices from options under "Preferences" on the cookie banner to store Type 3 cookies. For Cookie Banner v2 this cookie stores: -'0' when the OOTB cookie banner for the site is enabled and user has not explicitly clicked "Accept" or "Reject" or "Confirmed" their choices from "Preferences". -'1' if the user has explicitly clicked "Accept" in the cookie banner or "Confirmed" their choices from "Preferences". -'2' if user clicked "Reject". Configurable (Default = 6 months). This cookie is not session specific (persistent) and will be maintained across sessions. This cookie is not dropped if OOTB cookie banner is disabled. If the banner is enabled and this cookie is removed from the browser, then new Type 3 cookies will not be stored in the browser. LithiumTargetingCookiesAccepted (for Cookie Banner v2) 1 Stores the information of whether the user has given explicit consent by clicking "Accept", "Reject" or "Confirmed" their choices from options under "Preferences" on the cookie banner to store Type 4 cookies. For Cookie Banner v2 this cookie stores: -'0' when the OOTB cookie banner for the site is enabled and user has not explicitly clicked "Accept" or "Reject" or "Confirmed" their choices from "Preferences". -'1' if the user has explicitly clicked "Accept" in the cookie banner or "Confirmed" their choices from "Preferences". -'2' if user clicked "Reject". Configurable (Default = 6 months). This cookie is not session specific (persistent) and will be maintained across sessions. This cookie is not dropped if OOTB cookie banner is disabled. If the banner is enabled and this cookie is removed from the browser, then new Type 4 cookies will not be stored in the browser. LithiumPerformanceCookiesAccepted (for Cookie Banner v2) 1 Stores the information of whether the user has given explicit consent by clicking "Accept", "Reject" or "Confirmed" their choices from options under "Preferences" on the cookie banner to store Type 2 cookies. For Cookie Banner v2 this cookie stores: -'0' when the OOTB cookie banner for the site is enabled and user has not explicitly clicked "Accept" or "Reject" or "Confirmed" their choices from "Preferences". -'1' if the user has explicitly clicked "Accept" in the cookie banner or "Confirmed" their choices from "Preferences". -'2' if user clicked "Reject". Configurable (Default = 6 months). This cookie is not session specific (persistent) and will be maintained across sessions. This cookie is not dropped if OOTB cookie banner is disabled. If the banner is enabled and this cookie is removed from the browser, then new Type 2 cookies will not be stored in the browser. _pendo_meta.* 4 Cookie is used by Communities to show in-app feature guides in the "Community Admin" section Persistent None _pendo_accountId.* 4 Cookie is used by Communities to show in-app feature guides in the "Community Admin" section Persistent None _pendo_visitorId.* 4 Cookie is used by Communities to show in-app feature guides in the "Community Admin" section Persistent None mPulse 2 mPulse enables real-time performance monitoring and analysis of the community and helps improve over... 7 days The mPulse tools and dashboards from within Akamai will no longer contain the relevant real user measurement data. kh-local-storage (for Aurora only) 3 Introduced in Aurora 23.5/23.6 when it was discovered that Android apps need to have local storage enabled to embed a community via WebView. If local storage is not enabled, the app falls back to using this cookie for local storage instead. Session Mobile Android apps that embed a community using WebView and do not have local storage enabled will fail to render pages. LithiumImpersonatedUser (for Aurora only) 3 Keeps reference of the user being impersonated when the Switch Member feature is enabled. 30 minutes Switch Member feature would not work as cookie is used to identify the impersonated user. kh-sso 1 When the bounce URL is set in the SSO properties, the user is redirected to said URL if it’s not authenticated. In order to avoid a redirection loop, this cookie is set to mark that the user has already been redirected once. Session If the bounce URL is set in the SSO properties, the user may enter a redirection loop and be unable to access the community. LithiumUserExternalVideoConsent 1 Remembers users' preferences to consent to cookies originating from external video providers 180 days / 6 months Users are asked to consent to cookies originating from external video providers LithiumLocalePreferences (For Classic and Aurora communities) 3 Used to keep track of the user’s preferred language 24 hours Increase in number of calls to verify user language preference. Language preference order may be altered or may default to browser selected preference. For Aurora - If this cookie is not present, a query will be executed to retrieve the language. If the user does not have a value in their preferences, we will use the browser's `Accept-Language` header. LithiumToggleTextKeys 3 Used to enable toggle text key functionality in end-user app. 24 hours Toggle text keys functionality would not show on end-user app and therefore could not be used. LithiumLocalizedCategoryLocalePreference (Aurora only) 3 Used to keep track of the users selected language in the language selector when Localized Community is enabled in Aurora. 24 hours Users selected language from the language selector will not persist. Language preference will shift back to the language retrieved from the users browser `Accept-Language` header. csrf-aurora 1 Cross-site request protection Session Users cannot use the product LithiumTimezonePreferences 3 Stores timezone information used to render dates/times within the community interface. Prior to authentication, the cookie defaults to the community‑configured timezone. Upon user authentication, the cookie is updated with the user’s preferred timezone (derived from profile settings during login), enabling accurate local‑time display of timestamps, event schedules, and other time‑based community content. 24 hours Increase in number of calls to verify user timezone preference. Timezone preference may be altered or may default to community default timezone (typically US/Pacific). Timestamps displayed on mouseover may show incorrect timezone until page refresh or cookie is re-synced. Community Analytics Cookies Cookie Name Type Description and Purpose Expiration Time/Type If removed, disabled, or not accepted SIP|ws 3 Tracks the workspace to redirect to after a session timeout 1 day All Khoros Community cookies also apply to Community Analytics Khoros Care cookies Cookie Name Type Description and Purpose Expiration Time/Type If removed, disabled, or not accepted X-TOKEN-ID 1 Protects against cross-site scripting Session This is a security token. It is critical for the application to run PLAY_SESSION 1 This is the main session cookie Session This is the main session cookie. It is critical for the application to run __sdx_page 3 Stores the user’s current application tab 14 days When a user reloads the page, the user is redirected to the default tab instead of to the last tab used in the application PLAY_LANG 3 Retrieves the user’s language 14 days This is used only when LSW cannot detect the browser language and a user has no language set Khoros Care Analytics Cookies Cookie Name Type Description and Purpose Expiration Time/Type If removed, disabled, or not accepted XSessionID 1 This is the main session cookie 24 hours This is the main session cookie. It is critical for the application to run JSESSIONID 3 This is an auto-generated JSP cookie Session The application does not rely on this cookie but uses the cookie occasionally to auto-generate UUIDs Care Publisher Cookies Cookie Name Type Description and Purpose Expiration Time/Type If removed, disabled, or not accepted TOCOMA-CID 1 The user’s main session cookie Expires when the browser session ends The application will not run Khoros Marketing Cookies In addition to the _ga cookie used by Khoros Communities (see the “Khoros Communities cookies” chart above), Khoros Marketing also uses the following cookies: Note: Khoros Experiences customers can set additional cookies on websites where they publish visualizations created by the Khoros product, in addition to the standard cookies disclosed below. These cookies are set by social networks when a user signed in to the social network visits the website. Description and Purpose Cookie Name Type Expiration Time/Type Consequence if removed, disabled, or not accepted sf-ui.login.spredfast.com 3 - Functional Expanded user auth info Persistent None sfauth-login.spredfast.com 1 - Strictly necessary User Auth Info 12 hours Users cannot use the products sfjwt-login.spredfast.com 1 - Strictly necessary User Auth Info 12 hours Users cannot use the products sfcsrf-login.spredfast.com 1 - Strictly necessary Cross-site request protection 12 hours Users cannot use the products sfsig-login.spredfast.com 1 - Strictly necessary User Auth Info signature 12 hours Users cannot use the products _ga 2- Functional Google Analytics - Used to distinguish users. 2 years None _gid 2- Functional Google Analytics - Used to distinguish users. 24 hours None _gat 2- Functional Google Analytics - Used to throttle request rate. If Google Analytics is deployed via Google Tag Manager, this cookie will be named _dc_gtm_<property-id>. 1 minute None _pendo_accountId.* 4 - Tracking, targeting and sharing Cookie is used by marketing software for user analytics Persistent None _pendo_meta.* 4 - Tracking, targeting and sharing Cookie is used by marketing software for user analytics Persistent None _pendo_visitorId.* 4 - Tracking, targeting and sharing Cookie is used by marketing software for user analytics Persistent None PHPSESSID 1 - Strictly necessary Only contain a reference to a session stored on the web server. No information is stored in the user's browser and this cookie can only be used by the current web site. Session Users cannot use the product csrf_token 1 - Strictly necessary Cross-site request protection Session Users cannot use the product campaignTab 3 - Functional Used to track and restore last tab in Initiative Settings Session None _tweetriver_session 1 - Strictly necessary Only contain a reference to a session stored on the web server. No information is stored in the user's browser and this cookie can only be used by the current web site. 24 hours Users cannot use the product _tweetriver_session 1 - Strictly necessary Only contain a reference to a session stored on the web server. No information is stored in the user's browser and this cookie can only be used by the current web site. 24 hours Users cannot use the product mr_inst_token 3 - Functional Allows users to like an Instagram status from Vizzes Session Users cannot like an Instagram status from Vizzes mr_pauth_t 1 - Strictly necessary Redirects the user after photo share Session User will not be redirected after sharing a photo poll-user-id 3 - Functional Tracks a random user id for submitting to a poll (so repeat votes can be tracked). Session Duplicate poll votes cannot be tracked. redirectToOldModeration 3 - Functional Redirects the user to old stream moderation tool Session May be deprecated or non-functioning at this time Customer and Third-Party Cookies on Khoros Communities Khoros customers may set additional cookies on Khoros Community in addition to the standard cookies disclosed above. These cookies are set and controlled by Khoros customers and their affiliates for various purposes such as website usage tracking (very common practice) and targeting for surveys or advertising in some cases. Khoros does not control the dissemination of such cookies. If you need more information on which additional cookies are set on the Community you are visiting, visit the community’s privacy section. You may also wish to review the How to control cookies section to view, remove, or block certain cookies. Note that disabling or removing cookies may have an adverse impact on the proper functioning of the community, and certain features may become disabled or unavailable. Cookies Set by Third-Party and External Sites Communities may contain embedded images, videos, and links to external and third-party websites. Khoros customers may also include syndicated content on their communities such as banner ads and similar embedded objects from their affiliates and partners. As a result, when you click on such an object you may be presented with cookies from the owner of that respective website where the content is hosted. Khoros does not control the dissemination of such cookies. Contact the relevant third party website for their privacy policy and cookie information. Note that disabling or removing cookies may have an adverse impact on the proper functioning of the community, and certain features may become disabled or unavailable. Khoros Bot Cookies Khoros recently acquired Flow.ai which provides Intent Detection and Suggested Responses in Enterprise Architecture and uses the following cookies in the provided cookie bar when accepted by the website visitor: Cookie Name Location Description Type Cloudfire Dashboard The cookie is used by CloudFare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. Strictly necessary Google Analytics Dashboard The cookie is used by Google analytics to calculate visitor, session, campaign data, user interaction with the website and keep track of site usage for the site''s analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. Performance Stripe Dashboard This cookie is used to enable payment on the website without storing any payment information on a server. Strictly necessary Atlas Cookies In addition to the AWSALBCO, AWSALB, _ga, LiSESSIONID, LithiumVisitor and VISITOR_BEACON cookies used by Khoros Communities (see the “Khoros Communities cookies” chart above) Khoros Atlas Community also uses the following cookies: Cookie Name Type Description and Purpose Expiration Time/Type __cfduid Necessary The cookie is used by cdn services like CloudFare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. 1 month _hjFirstSeen Analytics This is set by Hotjar to identify a new user’s first session. It stores a true/false value, indicating whether this was the first time Hotjar saw this user. It is used by Recording filters to identify new user sessions. 30 minutes _gat_UA-134360776-2 Other No description 1 minute _gat_UA-134360776-3 Other No description 1 minute _hjTLDTest Other No description session _hjid Other This cookie is set by Hotjar. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID. 1 year Munchkin Javascript Tracking API 4 Tracking of end-user page visits. Tracking of clicks to specific landing pages and external web pages. 720 days, and we're currently supporting Do Not Track functionality Contact Khoros For Privacy related requests email privacy [at] khoros [dot] com. Use a secure communication method such as PGP or SMIME for sharing sensitive information. Find Khoros' Privacy Policy. For Security related requests email [email protected]. Use a secure communication method such as PGP or SMIME for sharing sensitive information. For sales related and general inquiries, contact your designated Account Manager or visit our website.314KViews
Sign in to react to this post21Comments
Khoros Customer Data Retention and Destruction
Data Retention Customer data is generally retained for the duration of the customer’s contract with Khoros. Exceptions to this include: Khoros Marketing: Data imported from various social media platforms is retained for a rolling twenty four (24) months before it is automatically purged. Khoros Care: Data imported from various social media platforms is stored for the life of the agreement but can be viewed directly in the platform only for 24 months. Data can be exported from the Service via API for a period of 18 months. Khoros Community: Data processed within Khoros Community will be retained for the life of the agreement. While being retained, all customer data is retrievable and maintained per applicable legal, contractual and regulatory requirements. Customer data is available for 30 days from the date of termination or expiration of the agreement ("Data Retrieval Window"). Once the agreement ends, the data will be returned to the customer upon written request. If data is not requested by the customer, the customer agrees that Khoros has no further obligation to retain the data. Notes: (a) data on backup systems is maintained for 90 days and then deleted; (b) log files are maintained for up to twelve months and then deleted. During and after the life of the agreement, Khoros can use aggregated and anonymized data for metrics and reporting purpose. This data does not include any personal information. Data Backup and Restoration Backups are taken every day and are encrypted using AES 256-bit information. Backups are overwritten every 90 days. Access to the backups is restricted to authorized individuals. We conduct backup restoration testing annually. Data Retrieval At the expiration or termination of the agreement, if the customer wishes to have a copy of its data, the customer must send a written request via the support portal at https://supportportal.khoros.com/ within the Data Retrieval Period noted in the Data Retention section above. We security provide the extract for: Khoros Community content, one time and at no charge, in a machine-readable format. For all other Khoros Services, customers may download the content in a comma separated value (.csv) format. Khoros can provide additional assistance for data extractions at Khoros’s standard Professional Services rates. The availability of content for extraction or downloading from certain services will be limited as described above within the Data Retention section. Data Destruction The data is made available for 30 days from the agreement expiration or termination date. Unless otherwise required by applicable law, customer data is deleted after the Data Retrieval Window in accordance with the above 'Data Retention' section. The active databases are dropped from the production servers and data is permanently deleted according to NIST SP 800-88 guidelines.20KViews
Sign in to react to this post12Comments
Personal Data Inventory for Khoros Subscription Services
This document captures a complete inventory of personal data points used throughout Khoros products. Khoros relies on performance of a contract and/or legitimate interests in order to process the personal data contained in this document. Please scroll down to the charts below or simply click on one of the following product links to be redirected to the corresponding chart: MARKETING Data Element Source Subprocessor Recipients (If blank, none) Country Locations of subprocessors can be found here Retention/Deletion Campaigns/Initiatives User ID User-created Aurora - indefinitely until 30 days post-contract Roles User ID User-created Aurora - indefinitely until 30 days post-contract Approvals User ID User-created Aurora - indefinitely until 30 days post-contract Labels User ID User-created Aurora - indefinitely until 30 days post-contract Credentials User ID User-created Aurora - indefinitely until 30 days post-contract Notifier Recipient Email User-created Aurora - indefinitely until 30 days post-contract User Profile ID first name last name email avatar image mobile phone User-created Aurora - indefinitely until 30 days post-contract Directory Service Customer/Company User ID Company Administrator-created Aurora - indefinitely until 30 days post-contract FINEX (Financial Industry Export) outgoing content (publishing posts and care replies) snapshots of company user profile details in the system user approvals Generated nightly by the marketing system. AWS filesystem - 1 day (deleted and regenerated nightly) Suite navigation data User ID Captured by Pendo as users navigate the product suite. Indefinitely at Pendo until 30 days post-contract) Promotion Accounts User ID User-created Aurora - indefinitely until 30 days post-contract Promotions User ID User-created Aurora - indefinitely until 30 days post-contract Care analytics data User ID Generated by the Marketing system as user actions occur. Aurora - indefinitely until 30 days post-contract Redshift - 30 days Care Rules User ID User-created Aurora - indefinitely until 30 days post-contract whodex profiles Social Handles Name Profile Image Location Coordinates Country Code Follower Count Following Count Sourced from supported social networks via API Aurora - indefinitely until 30 days post-contract whodex profile author notes user id author notes User-created Aurora - indefinitely until 30 days post-contract export logs User ID Generated by the Marketing system as user actions occur. Kibana - 30 days analytics dashboards User ID User-created Aurora - indefinitely until 30 days post-contract plans User ID User-created Aurora - indefinitely until 30 days post-contract messages User ID User-created Aurora - indefinitely until 30 days post-contract Content Center assets User ID User-created Aurora - indefinitely until 30 days post-contract auto-labeling rules User ID User-created Aurora - indefinitely until 30 days post-contract comments User ID User-created Aurora - indefinitely until 30 days post-contract replies User ID User-created Aurora - indefinitely until 30 days post-contract retweets User ID User-created Aurora - indefinitely until 30 days post-contract streams User ID User-created Aurora - indefinitely until 30 days post-contract Stream Entities Author Bio Full Name profile Picture: username social network user id Post Contents Sourced from supported social networks via API. Aurora - indefinitely until 30 days post-contract Cassandra - 7 days Memcached - 1 day User user id full name Company Administrator-created Aurora - indefinitely until 30 days post-contract visualizations User ID User-created Aurora - indefinitely until 30 days post-contract spaces User ID User-created Aurora - indefinitely until 30 days post-contract spotlight reports User ID User-created Aurora - indefinitely until 30 days post-contract post search results Author Bio Full Name profile Picture: username social network user id Post Contents Sourced from supported social networks via API Cassandra - indefinitely until 30 days post-contract Stream Items Author Bio Full Name profilePicture: username social network user id Post Contents Sourced from supported social networks via API Cassandra - indefinitely until 30days post-contract Influencers whodex profile id User-created Aurora - indefinitely until 30 days post-contract TeamQueue data Generated by the Marketing system as user actions occur. Cassandra- 30 days post contract CARE Data Element Source Third-Party Recipients Country Locations can be found here Retention/Deletion Id Name Picture First name Last name FACEBOOK: Consumer data is retrieved through Facebook APIs after the company authenticates their Facebook Page(s) with Response. All consumer data is subject to Facebook's Terms of Service. Yes Deleted within 30 days of end of customer contract. User comments deleted in Facebook will also be deleted in Care based on Facebook notification. Id Username INSTAGRAM: Consumer data is retrieved through Instagram APIs after the company authenticates their Instagram Handle(s) with Response. All consumer data is subject to Instagram's Terms of Use. Yes Deleted within 30 days of end of customer of contract. Id GOOGLE BUSINESS MANAGER: Consumer data is received through streaming updates after company authenticates Business messages with Care. All consumer data is subject to Google's Business Messages Terms of Service. Yes Deleted within 30 days of end of customer contract. Name Username GOOGLE MY BUSINESS: Consumer data is received through Google MyBusiness APIs after company authenticates with Care. All consumer data is subject to Google's Terms of Service. Yes Deleted within 30 days of end of customer contract. Name RSS: Consumer data is received through RSS APIs after company authenticates with Care. Yes Deleted within 30 days of end of customer contract. Id Display name Profile image url YOUTUBE: Consumer data is retrieved through YouTube APIs after the company authenticates their YouTube Channel(s) with Response. All consumer data is subject to YouTube's Terms of Service. Yes Deleted within 30 days of end of customer contract. Id APPLE BUSINESS CHAT:Consumer data is received through streaming updates after company authenticates Apple Business Chat with Care. All consumer data is subject to Apple's Terms of Service. Yes Deleted within 30 days of end of customer contract. Id First name Last name WEB MESSANGER (SMOOCH): Within a secure chat, provided by Sunshine Conversations, consumers will share unstructured PII (i.e. the information will be shared within a chat conversation). This data will be ingested into Care. Yes Deleted within 30 days of end of customer contract. Id Name WECHAT: Consumer data is retrieved through WeChat's APIs after the company authenticates their WeChat Account(s) with Response. All consumer data is subject to WeChat's Terms of Service. Yes Deleted within 30 days of end of customer contract. Phone number SMS: Consumer data is retrieved through Twilio APIs after the company authenticates their SMS numbers with Care. All consumer data is subject to Twilio's Terms of Service. Yes Deleted within 30 days of end of customer contract. Phone number First name Last name WHATSAPP: Consumer data is retrieved through Smooch APIs after the company authenticates their WhatsApp numbers with Care. All consumer data is subject to WhatsApp's Terms of Service. Yes Deleted within 30 days of end of customer contract. Name Device information GOOGLE PLAY STORE REVIEWS Yes Deleted within 30 days of end of customer contract. Id Name Profile image url NETBASE Yes Deleted within 30 days of end of customer contract. Name IOS APP STORE REVIEWS Yes Deleted within 30 days of end of customer contract. Id First name Last name Bio Profile image LINKEDIN: Consumer data is retrieved through LinkedIn APIs after the company authenticates their LinkedIn Page(s) with Response. All consumer data is subject to LinkedIn's Terms of Service. Yes Deleted within 30 days of end of customer contract. RADIAN 6: This is a general listening integration that can bring in content from all of the other networks listed. We should no longer be using this provider. Yes Deleted within 30 days of end of customer contract. Id Name Profile image url YELP: Consumer data is retrieved through LinkedIn APIs after the company authenticates their Yelp Location(s) with Response. All consumer data is subject to Yelps Terms of Service. Yes Deleted within 30 days of end of customer contract. Id Display name Email Profile image url KHOROS COMMUNITY Yes Deleted within 30 days of end of customer contract. KHOROS BOT Data Element Source Third-Party Recipients Country Locations can be found here Retention/Deletion Name Timezone Language Profile picture Chat related data that can include personal data (Specified by customer in custom DPA) Facebook messenger MongoDB Google cloud On project removal On applied data retention policy Phone number Name Chat related data that can include personal data (Specified by customer in custom DPA) WhatsApp MongoDB Google cloud On project removal On applied data retention policy IP address Browser version Browser language Chat related data that can include personal data (Specified by customer in custom DPA) Web Widget MongoDB Google cloud On project removal On applied data retention policy Any shared files are removed after 90 days Name Chat related data that can include personal data (Specified by customer in custom DPA) Khoros MongoDB Google cloud On project removal On applied data retention policy Phone number Chat related data that can include personal data (Specified by customer in custom DPA) Twilio MongoDB Google cloud On project removal On applied data retention policy Phone number in case of WhatsApp or SMS Analytics metadata Google cloud On project removal COMMUNITY Data Element Source Third-Party Recipients Country Locations can be found here Retention/Deletion Author login (username) email address (except privacy guide) salted password hash (except SSO) SSO - from SSO identity provider (usually customer's propitiatory identity system via SSO cookie). Local with migration - from PS team or Administrator importing the info Local without migration - from users through initial registration Yes Mysql, Elasticsearch, Cassendra - indefinitely. Redis - 24 hours Author userId Created during the first initial interaction to the system, may it be SSO or import or registration Yes Mysql, Elasticsearch, Cassendra - indefinitely. Redis - 24 hours Author ICQ (optional) AIM (optional) Skype (optional) MSN (optional) Yahoo (optional) Bio (optional) Custom personal data fields (customizable per community) Except required custom fields, all are optional not related to any feature supported Entered by user either through initial registration or sub-sequential interaction with the community. For custom personal data fields, it could also possible be from SSO cookie. Yes Mysql, Elasticsearch, Cassendra - indefinitely. Redis - 24 hours Author Facebook access token Supported Feature: Facebook connect and integration Entered by user either through initial registration or sub-sequential interaction with the community Yes Mysel - indefinitely. Supported Feature: Profile picture Author profilePicture Entered by user either through initial registration or sub-sequential interaction with the community Yes Mysql - indefinitely. Redis - 24 hours Author IP address browser cookie string user agent http referrer headers From the http requests to the community Yes Mysql - indefinitely. Redis - 24 hours Community User Metrics Total Messages Posted Total Page Views Total Messages Read Board Topics Started Board Replies Blog Articles Posted Blog Comments Posted Ideas Posted Idea Comments Posted Questions Posted Q&A Replies Posted Answers Posted Q&A Comments Posted Total Board Views Total Logins Total Minutes Online Created by the community Yes Mysql, Elasticsearch indefinitely. Redis - 24 hours CX INSIGHTS Data Element Source Third-Party Recipients Country Locations can be found here Retention/Deletion Audio Recordings: Name Phone number Email address Physical address Dates directly related to an individual (birth, death, admission, etc.) Gender Username Security code/PIN Security questions Account number IMEI number Audio files provided by Khoros clients Amazon Web Services Earlier of 24 months after the audio recording was created or Agreement termination date Audio Recordings: Name Phone number Email address Physical address Dates directly related to an individual (birth, death, admission, etc.) Gender Username Security code/PIN Security questions Account number IMEI number Audio files provided by Khoros clients Amazon Web Servies MongoDB Google Cloud Platform Earlier of 24 months after the audio recording was created or Agreement termination date Conversation transcripts: Name Phone number Email address Physical address Dates directly related to an individual (birth, death, admission, etc.) Gender Username Security code/PIN Security questions Account number IMEI number Text-based conversation transcripts provided by Khoros clients Google Cloud Platform Earlier of 24 months after the audio recording was created or Agreement termination date Product Reviews and Surveys: Name Phone number Email address Physical address Gender Age Username Account number IP address MAC address Text-based product/service review data provided by Khoros clients Amazon Web Services MongoDB Google Cloud Platform Earlier of 24 months after the audio recording was created or Agreement termination date Social Media Posts: Social network user ID Name Username Post contents From social networks via API, provided by Khoros clients, or third-party data aggregation sources Amazon Web Services MongoDB Google Cloud Platform Earlier of 24 months after the audio recording was created or Agreement termination date Web Session Data: Username IP address MAC address Email address Web session recording applications Amazon Web Services MongoDB Earlier of 24 months after the audio recording was created or Agreement termination date User Access Data: Email address IP address User created activity Okta Three (3) months from the date of the user session User Access Data: Name Email address User created activity Zendesk Indefinitely at Zendesk until 90 days post-contract termination User Access Data: Email address IP address User created activity Alienvault Sumo Logic Twelve (12) months from the date of the user session User Access Data: Name Email address User created activity Pendo.io Indefinitely at Pendo.io until 30 days post-contract termination25KViews
Sign in to react to this post0Comments
What companies are subprocessors to Khoros?
Data Location & Subprocessor Guide Khoros uses subprocessors in its applications to help it perform certain Services. Suprocessors are third-party entities with whom Khoros contracts to perform these Services and who may process customers’ personal data. Khoros contractually requires its subprocessors to comply with security and data privacy standards that are at least as protective as those that Khoros commits to its customers. For information on our subprocessors, please scroll down to the charts below or simply click on one of the following links to be redirected to the corresponding table: What has changed since our last version: We updated our Business Operational Subprocessors. MARKETING SUBPROCESSORS Subprocessor Purpose Data Hosting Location Customer Location AWS USA Cloud hosting USA Worldwide Airship Mobile push notifications which might contain PII USA, EU Worldwide Fastly Content delivery network Worldwide (location list at: https://www.fastly.com/network-map) Worldwide Pendo In-app help, guidance, and announcements USA Worldwide SendGrid (Twilio) Email service provider used to send emails USA, UK, India, and Japan Worldwide Sumo Logic Log collection and storage USA Worldwide Twilio Provides programmable communication products and services, primarily in the form of APIs USA Worldwide Zencoder (Brightcove) Video transcoding; Although it does not handle PII, it may have access to unreleased marketing assets USA, Australia, Mexico, Singapore, UK, Spain, France, Germany, and Sweden Worldwide OPTIONAL MARKETING SUBPROCESSORS Talkwalker Deep listening services for select Strategic Services Customers EU (Germany) Worldwide CARE SUBPROCESSORS Subprocessor Purpose Data Hosting Location Customer Location AWS USA Cloud hosting USA USA and Canada Customers EMEA/APAC Customers solely for authentication data* AWS Ireland Cloud hosting Ireland EMEA Customers* AWS Australia Cloud hosting Australia APAC Customers* Pendo In-app help, guidance, and announcements USA Worldwide Sendgrid (Twilio) Email services provider used to send emails USA, UK, India, and Japan Worldwide Sumo Logic Log collection and storage USA USA, Canada, and EMEA Customers Sumo Logic Log collection and storage Australia APAC Customers Sunshine Conversations Extends conversational capabilities USA and EU Worldwide Twilio Provides programmable communication products and services, primarily in the form of APIs USA Worldwide OPTIONAL CARE SUBPROCESSORS Box File storage for Customers using the “File Preview Feature” USA Worldwide Cloud Elements API integration platform for CRM USA and Ireland Worldwide * = User profile and authentication data for the sole purpose of providing a unified log-in experience will be hosted in AWS USA for all Care customers. All other customer data is hosted in region where customer is situated. KHOROS BOT SUBPROCESSORS Subprocessor Purpose Data Hosting Location Customer Location Auth0 User authentication Germany Worldwide AWS EU West 1 Cloud hosting Amsterdam, Germany, and Luxembourg Worldwide AWS Ireland Cloud hosting Ireland Worldwide Cloudflare Web firewall and CDN Worldwide Worldwide Customer.io CRM USA Worldwide MongoDB Database management Belgium Worldwide OPTIONAL KHOROS BOT SUBPROCESSORS Google Ads (and analytics) Advertising USA Worldwide Vertex AI (Google Cloud) Provides advanced machine learning to enhance Khoros Bot and Agent Assist functionality, including large language models (LLMs) USA (Oregon) US and Canada Customers Vertex AI (Google Cloud) Provides advanced machine learning to enhance Khoros Bot and Agent Assist functionality, including large language models (LLMs) UK EMEA Customers Vertex AI (Google Cloud) Provides advanced machine learning to enhance Khoros Bot and Agent Assist functionality, including large language models (LLMs) Australia APAC Customers Sendgrid (Twilio) Email provider USA Worldwide Sentry.io Error reporting USA Worldwide COMMUNITY SUBPROCESSORS Subprocessor Purpose Data Hosting Location Customer Location AWS USA Cloud hosting USA USA, Canada, and APAC** Customers AWS Ireland Cloud hosting Ireland EMEA Customers AWS Australia Cloud hosting Australia APAC** Customers Akismet Spam detection USA and Australia Worldwide Clarotest Consulting Lab S.R.L. Some access to customer data as part of outage mitigation Argentina Worldwide Pendo In-app help, guidance, and announcements USA Worldwide Sendgrid (Twilio) Email services provider used to send emails USA, UK, India, and Japan Worldwide Sumo Logic Log collection and storage USA Worldwide Sunshine Conversations Extends conversational capabilities USA and EU Worldwide OPTIONAL COMMUNITY SUBPROCESSORS Akamai Technologies Content delivery network Worldwide (location list at: https://www.akamai.com/us/en/locations.jsp) Worldwide AWS Australia Cloud hosting Australia APAC** Customers Brightcove Video playback and storage USA, Australia, Mexico, Singapore, UK, Spain, France, Germany, and Sweden Worldwide Box File storage for Customers using the “File Preview Feature” USA Worldwide ETI Migrations Bulgaria, Italy, and UK Worldwide ** APAC Customers with Khoros Communities created prior to July 2024 will be hosted via AWS USA unless they have expressly opted to migrate to AWS Australia (fees apply). APAC Customers with Khoros Communities created July 2024 and after will be hosted via AWS Australia. BUSINESS OPERATIONAL SUBPROCESSORS Subprocessor Purpose Data Hosting Location Customer Location Domo Business intelligence and data visualization tool USA Worldwide Atlassian (Jira) Product support tool for Professional Services issue tracking and project management USA Worldwide Salesforce*** Customer relationship management USA Worldwide Workato System integration USA Worldwide Google LLC Email and document management USA/EU Worldwide Crossover Markets, LLC Recruiting, HR services USA Worldwide VoiceFlow, Inc. Support Chatbot Canada Worldwide ESW Operations, LLC Customer support platform EU Worldwide OPTIONAL BUSINESS OPERATIONAL SUBPROCESSORS Litmos Learning management system used to host product training content USA Worldwide Read AI, Inc. Meeting assistant, used for recording, taking notes and summarizing meetings USA Worldwide *** = Salesforce may be used in conjunction with other third-party applications or add-ons.50KViews
Sign in to react to this post6Comments
GDPR and CCPA Compliance
On May 25, 2018, the General Data Protection Regulation (GDPR) went into effect. GDPR is a set of data privacy laws across Europe that are designed to protect EU citizens’ data privacy and reshape the way organizations approach data privacy. On January 1, 2020, the California Consumer Privacy Act of 2018 (CCPA) will go into effect and enforcement will begin July 1, 2020. The CCPA is a California privacy law that is applicable to businesses doing business in California and that meet one of three revenue thresholds. It also applies to service providers of those businesses, who are defined under the CCPA as a company handling PI on behalf of a business, for a business purpose. The following is an update on Khoros’s compliance efforts as they relate to the GDPR and CCPA: We have worked with outside EU counsel to ensure we are correctly interpreting how the GDPR affects Khoros specifically, and to ensure we are handling EU personal data correctly. For example, we confirmed our interpretations of consent requirements and other legal bases for processing personal data and exporting personal data from the EEA with our EU counsel. Additionally, Khoros has been working with outside U.S. counsel to ensure we are compliant with the CCPA. One important point to make clear is that Khoros will never sell our customers’ personal information for any reason at all and we will contractually agree to the same. Khoros has updated its DPA template to expand its scope not just to EU personal data, but to PI covered under the CCPA also. Our DPA template also contains all the necessary GDPR flow-down provisions and accurately reflects the processes used by Khoros to comply with privacy laws. We would be happy to provide you a copy to make it easy for you to check the box in regards to your own GPDR/CCPA compliance efforts. Khoros is continually examining and documenting our internal processes and any aspects of our product portfolio that relate to personal data handling, not just to ensure regulatory compliance, but more importantly to achieve best practices and satisfy our customers’ needs. If you’re looking for more information, check out the links below to our product specific FAQs, privacy policies, details on our subprocessors, and the official sites for GDPR and CCPA. And I know this is complicated, so if you have specific questions, leave them in the comments and I’ll make sure they get addressed. GDPR and CCPA for Communities GDPR and CCPA for Care GDPR and CCPA for Marketing Khoros Privacy Policy Subprocessor web page Official CCPA site Official GDPR site48KViews
Sign in to react to this post12Comments
You’ve seen all recent content